1 © 2004, Cisco Systems, Inc. All rights reserved. Chapter 7 VLAN and VPNs.

Slides:



Advertisements
Similar presentations
Virtual Trunk Protocol
Advertisements

© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implement VTP LAN Switching and Wireless – Chapter 4.
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—2-1 Extending Switched Networks with Virtual LANs Introducing VLAN Operations.
Virtual LANs.
VLANs Module 2. 2 VLANs  VLANs  Trunking  VLAN Trunking Protocol (VTP)
VLAN Trunking protocol- Chapter 4
1 27-Jun-15 S Ward Abingdon and Witney College VLAN Trunking protocol CCNA Exploration Semester 3 Chapter 4.
Virtual LANs. VLAN Overview Segmentation Flexibility Security 3rd floor 2nd floor 1st floor SALESHRENG A VLAN = A broadcast domain = Logical network (subnet)
© Wiley Inc All Rights Reserved. CCNA: Cisco Certified Network Associate Study Guide CHAPTER 8: Virtual LANs (VLANs)
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—2-1 Extending Switched Networks with Virtual LANs Configuring VLANs.
LOGO Local Area Network (LAN) Layer 2 Switching and Virtual LANs (VLANs) Local Area Network (LAN) Layer 2 Switching and Virtual LANs (VLANs) Chapter 6.
Sybex CCNA Chapter 9: VLAN’s Instructor & Todd Lammle.
© 2009 Cisco Systems, Inc. All rights reserved. SWITCH v1.0—2-1 Implementing VLANs in Campus Networks Applying Best Practices for VLAN Topologies.
VLAN & VPNs Chapter 8 VLAN & VPNs By Dr.Sukchatri P.
VLAN Trunking Protocol (VTP) W.lilakiatsakun. VLAN Management Challenge (1) It is not difficult to add new VLAN for a small network.
Switching Chapter 9 Switching By Dr.Sukchatri P..
VLAN Trunking Protocol
CCNA Guide to Cisco Networking Fundamentals Fourth Edition
Switching in an Enterprise Network
Switching Basics and Intermediate Routing CCNA 3 Chapter 9
VLAN Trunking Protocol (VTP)
CN2668 Routers and Switches (V2) Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Building Cisco Multilayer Switched Networks (BCMSN)
VLAN Trunking Protocol (VTP)
© 1999, Cisco Systems, Inc. 7-1 Chapter 7 Extending Switched Networks with Virtual LANs.
Chapter 9 Virtual LANs (VLANs). Setup 1 Setup 2.
CCNA 3 Week 9 VLAN Trunking. Copyright © 2005 University of Bolton Origins Dates back to radio and telephone Trunk carries multiple channels over a single.
Cisco 3 - LAN Perrine. J Page 110/20/2015 Chapter 8 VLAN VLAN: is a logical grouping grouped by: function department application VLAN configuration is.
© 2002, Cisco Systems, Inc. All rights reserved..
LOGO Local Area Network (LAN) Layer 2 Switching and Virtual LANs (VLANs) Local Area Network (LAN) Layer 2 Switching and Virtual LANs (VLANs) Chapter 6.
Medium-Sized Switched Network Construction NetPro-ITI Implementing VLANs and Trunks.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 8 Virtual LANs.
Switching Basics and Intermediate Routing CCNA 3 Chapter 8.
© 1999, Cisco Systems, Inc. 6-1 Chapter 6 Catalyst Switch Operations.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 9 Virtual Trunking Protocol.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 8 Virtual LANs Cisco Networking Academy.
© 1999, Cisco Systems, Inc. 4-1 Chapter 10 Controlling Campus Device Access Chapter 4 Defining Common Workgroups © 1999, Cisco Systems, Inc
Page 1 Switching Technologies Lecture 4C Hassan Shuja 03/28/2006.
Switching Topic 2 VLANs.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Switching in an Enterprise Network Introducing Routing and Switching in the.
Virtual Local Area Networks (VLANs) Part II
Switching Topic 3 VTP. Agenda VTP basics Components Frames and advertisements Domains and revision numbers VTP operations VTP pruning VTP issues.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 9 VLAN Trunking Protocol Cisco Networking Academy.
Configuring VLAN Chapter 14 powered by DJ 1. Chapter Objectives At the end of this Chapter you will be able to:  Understand basic concept of VLAN  Configure.
Chapter 4 Version 1 Virtual LANs. Introduction By default, switches forward broadcasts, this means that all segments connected to a switch are in one.
CCNA3 v3 Module 9 v3 CCNA 3 Module 9 JEOPARDY K. Martin.
VLAN Trunking Protocol
VLAN Trunking Protocol (VTP)
1 15-Mar-16 VLAN Trunking protocol CCNA Exploration Semester 3 Chapter 4.
VTP VLAN Trunking Protocol Create once and send to the other switches. VTP is a messaging protocol that uses Layer 2 trunk frames to manage the addition,
LAN Switching Virtual LANs. Virtual LAN Concepts A LAN includes all devices in the same broadcast domain. A broadcast domain includes the set of all LAN-connected.
Exploration 3 Chapter 4. What is VTP? VTP allows a network manager to configure a switch so that it will propagate VLAN configurations to other switches.
© 2003, Cisco Systems, Inc. All rights reserved. 2-1 Implementing VLAN Trunks.
Chap 4 – Implement VTP Learning Objectives
Switching and VLANs.
© 2002, Cisco Systems, Inc. All rights reserved.
Switching and VLANs.
© 2002, Cisco Systems, Inc. All rights reserved.
Extending Switched Networks with Virtual LANs
Purpose: The purpose of this chapter is to describe VLAN operations on the Catalyst switches. Timing: This module should take about two hours to present.
VLAN Trunking Protocol
Medium-Sized Switched Network Construction
VLAN Trunking Protocol
Switching and VLANs.
Switching and VLANs.
Implementing VLAN Trunks
Switching Basics and Intermediate Routing CCNA 3 Chapter 9
Chapter 2: Scaling VLANs
© 2002, Cisco Systems, Inc. All rights reserved.
Presentation transcript:

1 © 2004, Cisco Systems, Inc. All rights reserved. Chapter 7 VLAN and VPNs

222 © 2004, Cisco Systems, Inc. All rights reserved. Objectives Upon completion of this chapter, you will be able to perform the following tasks: Configure a VLAN Configure VLAN Trunking Protocol (VTP) Configure a switch for trunking Verify VLAN connectivity Verify spanning-tree operations

333 © 2004, Cisco Systems, Inc. All rights reserved. Contents A switch connecting three segments Configuration VLAN (Cisco) Private network Hybrid network Virtual private networks VPN techniques Authentication Encryption Tunneling Addressing in VPN

444 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Overview Segmentation Flexibility Security 3rd floor 2nd floor 1st floor SALES HR ENG A VLAN = A broadcast domain = Logical network (subnet)

555 © 2004, Cisco Systems, Inc. All rights reserved. A switch connecting three segments

666 © 2004, Cisco Systems, Inc. All rights reserved. A switch using VLAN software

777 © 2004, Cisco Systems, Inc. All rights reserved. Two switches in a backbone using VLAN software

888 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Operations Switch A Green VLAN Black VLAN Red VLAN Each logical VLAN is like a separate physical bridge

999 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Operations Switch A Green VLAN Black VLAN Red VLAN Switch B Green VLAN Black VLAN Red VLAN Each logical VLAN is like a separate physical bridge VLANs can span across multiple switches

10 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Operations Switch A Green VLAN Black VLAN Red VLAN Switch B Green VLAN Black VLAN Red VLAN Trunk Each logical VLAN is like a separate physical bridge VLANs can span across multiple switches Trunks carries traffic for multiple VLANs Fast Ethernet

11 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Membership Modes VLAN5 Static VLANDynamic VLAN MAC = Trunk VMPS = vlan 10 VLAN10 Port e0/9 Port e0/4

12 © 2004, Cisco Systems, Inc. All rights reserved. ISL Tagging Performed with ASIC Not intrusive to client stations, client does not see the ISL header Effective between switches, routers and switches, switches and servers with ISL network interface cards ISL trunks enable VLANs across a backbone VLAN Tag added by incoming port VLAN Tag stripped by forwarding port Inter-Switch Link carries VLAN identifier

13 © 2004, Cisco Systems, Inc. All rights reserved. ISL Encapsulation ISL Header 26 bytes Encapsulated Ethernet frame CRC 4 bytes Frames encapsulated with ISL header and CRC Support for many VLANs (1024) VLAN field BPDU bit DATypeUserSALEN VLAN AAAA03 BPDU HSAVLAN BPDU INDEXRES

14 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Trunking Protocol (VTP) A messaging system that advertises VLAN configuration information Maintains VLAN configuration consistency throughout a common administrative domain VTP sends advertisements on trunk ports only Support mixed media trunks (Fast Ethernet, FDDI, ATM) 1. “ new vlan added ” 3.Sync to the latest vlan information 2 VTP Domain “ ICND ”

15 © 2004, Cisco Systems, Inc. All rights reserved. VTP Modes Server Client Transparent Sends/forwards advertisements Synchronize Not saved in NVRAM Create vlans Modify vlans Delete vlans Sends/forwards advertisements Synchronize Saved in NVRAM Create vlans Modify vlans Delete vlans Forwards advertisements Does not synchronize Saved in NVRAM

16 © 2004, Cisco Systems, Inc. All rights reserved. How VTP Works VTP advertisements are sent as multicast frames VTP servers and clients synchronized to latest revision number VTP advertisement are sent every five minutes or when there is a change

17 © 2004, Cisco Systems, Inc. All rights reserved. VTP advertisements are sent as multicast frames VTP servers and clients synchronized to latest revision number VTP advertisement are sent every five minutes or when there is a change How VTP Works 1.Add new VLAN 2.Rev 3 --> Rev 4 Server Client 4.Rev 3 --> Rev 4 5.Sync new vlan info 33 4.Rev 3 --> Rev 4 5.Sync new vlan info

18 © 2004, Cisco Systems, Inc. All rights reserved. VTP Pruning Increases available bandwidth by reducing unnecessary flooded traffic Example: Station A sends broadcast, broadcast is only flooded toward any switch with ports assigned to the red VLAN Switch 4 Switch 2 Switch 6Switch 3Switch 1 Port 2 Flooded traffic is pruned Red VLAN Port 1 Switch 5 A B

19 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Configuration Guidelines Maximum number of VLANs is switch-dependent Catalyst 1900 supports 64 VLANs with a separate spanning tree per VLAN VLAN1 is One of the factory default VLANs CDP and VTP advertisements are sent on VLAN1 Catalyst 1900 IP address is in the VLAN1 broadcast domain Must be in VTP server or transparent mode to create, add, or delete VLANs

20 © 2004, Cisco Systems, Inc. All rights reserved. VLAN Configuration Steps Enable VTP (optional) Enable trunking Create VLANs Assign VLAN to ports

21 © 2004, Cisco Systems, Inc. All rights reserved. VTP domain name VTP mode (server/client/transparent) — VTP server mode is the default VTP pruning VTP password VTP trap VTP Configuration Guidelines Use caution when adding a new switch into an existing domain. A new switch should be added in client mode to prevent the new switch from propagating incorrect VLANs information Use the delete vtp command to reset the VTP revision number

22 © 2004, Cisco Systems, Inc. All rights reserved. Creating a VTP Domain vtp [server | transparent] [domain domain-name] [trap {enable | disable}] [password password] [pruning {enable | disable} wg_sw_a(config)#

23 © 2004, Cisco Systems, Inc. All rights reserved. Creating a VTP Domain wg_sw_a#conf terminal Enter configuration commands, one per line. End with CNTL/Z wg_sw_a(config)#vtp transparent wg_sw_a(config)#vtp domain switchlab vtp [server | transparent] [domain domain-name] [trap {enable | disable}] [password password] [pruning {enable | disable} wg_sw_a(config)#

24 © 2004, Cisco Systems, Inc. All rights reserved. Verifying VTP Configurations wg_sw_a#show vtp

25 © 2004, Cisco Systems, Inc. All rights reserved. Verifying VTP Configurations wg_sw_a#show vtp VTP version: 1 Configuration revision: 4 Maximum VLANs supported locally: 1005 Number of existing VLANs: 6 VTP domain name : switchlab VTP password : VTP operating mode : Transparent VTP pruning mode : Enabled VTP traps generation : Enabled Configuration last modified by: at :00:00 wg_sw_a#show vtp

26 © 2004, Cisco Systems, Inc. All rights reserved. Defining a Trunk trunk [on | off | desirable | auto | nonegotiate] wg_sw_a(config-if)# On = Set trunk on and negotiate with other side Off = Set trunk off and negotiate with other side Desirable = Negotiate with other side. Trunk on if other side is on, desirable, or auto Auto = Will be a trunk only if the other side is on or desirable Non-negotiate = Set trunk on and will not negotiate

27 © 2004, Cisco Systems, Inc. All rights reserved. Defining a Trunk wg_sw_a#conf terminal Enter configuration commands, one per line. End with CNTL/Z wg_sw_a(config)#interface f0/26 wg_sw_a(config-if)#trunk on First trunk port(Port A) On = Set trunk on and negotiate with other side Off = Set trunk off and negotiate with other side Desirable = Negotiate with other side. Trunk on if other side is on, desirable, or auto Auto = Will be a trunk only if the other side is on or desirable Non-negotiate = Set trunk on and will not negotiate trunk [on | off | desirable | auto | nonegotiate] wg_sw_a(config-if)#

28 © 2004, Cisco Systems, Inc. All rights reserved. Verifying a Trunk wg_sw_a#show trunk [A | B]

29 © 2004, Cisco Systems, Inc. All rights reserved. Verifying a Trunk wg_sw_a#show trunk a DISL state: On, Trunking: On, Encapsulation type: ISL wg_sw_a#show trunk [A | B]

30 © 2004, Cisco Systems, Inc. All rights reserved. Adding a VLAN vlan vlan# [name vlan-name] wg_sw_a(config)#

31 © 2004, Cisco Systems, Inc. All rights reserved. Adding a VLAN wg_sw_a#conf terminal Enter configuration commands, one per line. End with CNTL/Z wg_sw_a(config)#vlan 9 name switchlab2 vlan vlan# [name vlan-name] wg_sw_a(config)#

32 © 2004, Cisco Systems, Inc. All rights reserved. Verifying a VLAN wg_sw_a#show vlan [vlan#]

33 © 2004, Cisco Systems, Inc. All rights reserved. Verifying a VLAN wg_sw_a#sh vlan 9 VLAN Name Status Ports switchlab2 Enabled VLAN Type SAID MTU Parent RingNo BridgeNo Stp Trans1 Trans Ethernet Unkn wg_sw_a#show vlan [vlan#]

34 © 2004, Cisco Systems, Inc. All rights reserved. Modifying a VLAN Name vlan vlan# name vlan-name wg_sw_a#conf terminal Enter configuration commands, one per line. End with CNTL/Z wg_sw_a(config)#vlan 9 name switchlab90 wg_sw_a#show vlan 9 VLAN Name Status Ports switchlab90 Enabled wg_sw_a(config)#

35 © 2004, Cisco Systems, Inc. All rights reserved. Assigning Switch Ports to a VLAN vlan-membership {static {vlan#} | dynamic} wg_sw_a(config-if)#

36 © 2004, Cisco Systems, Inc. All rights reserved. Assigning Switch Ports to a VLAN wg_sw_a#conf terminal Enter configuration commands, one per line. End with CNTL/Z wg_sw_a(config)#interface ethernet 0/8 wg_sw_a(config-if)#vlan-membership static 9 vlan-membership {static {vlan#} | dynamic} wg_sw_a(config-if)#

37 © 2004, Cisco Systems, Inc. All rights reserved. Verifying VLAN Membership wg_sw_a#show vlan-membership

38 © 2004, Cisco Systems, Inc. All rights reserved. Verifying VLAN Membership wg_sw_a#show vlan-membership Port VLAN Membership Type Port VLAN Membership Type Static 13 1 Static 2 1 Static 14 1 Static 3 1 Static 15 1 Static 4 1 Static 16 1 Static 5 1 Static 17 1 Static 6 1 Static 18 1 Static 7 1 Static 19 1 Static 8 9 Static 20 1 Static Note: port 1=e0/1, port 2=e0/ wg_sw_a#show vlan-membership

39 © 2004, Cisco Systems, Inc. All rights reserved. Verifying Spanning Tree wg_sw_a#show spantree {vlan number}

40 © 2004, Cisco Systems, Inc. All rights reserved. Verifying Spanning Tree wg_sw_a#show spantree 1 VLAN1 is executing the IEEE compatible Spanning Tree Protocol Bridge Identifier has priority 32768, address 0050.F037.DA00 Configured hello time 2, max age 20, forward delay 15 Current root has priority 0, address 00D0.588F.B600 Root port is FastEthernet 0/26, cost of root path is 10 Topology change flag not set, detected flag not set Topology changes 53, last topology change occured 0d00h17m14s ago Times: hold 1, topology change 8960 hello 2, max age 20, forward delay 15 Timers: hello 2, topology change 35, notification 2 Port Ethernet 0/1 of VLAN1 is Forwarding Port path cost 100, Port priority 128 Designated root has priority 0, address 00D0.588F.B600 Designated bridge has priority 32768, address 0050.F037.DA00 Designated port is Ethernet 0/1, path cost 10 Timers: message age 20, forward delay 15, hold 1 wg_sw_a#show spantree {vlan number}

41 © 2004, Cisco Systems, Inc. All rights reserved. Visual Objective core_ server 10.x.x.1 wg_sw_a wg_sw_l wg_pc_a wg_pc_l e0/1 fa0/26 (port A) e0/1 fa0/26 (port A) fa0/1fa0/12 fa0/24 core_sw_a ISL SUBNETVLANPOD wg_ro_x, wg_sw_x, core_sw_a wg_pc_a, core_server wg_pc_b, core_server wg_pc_c, core_server wg_pc_d, core_server wg_pc_e, core_server wg_pc_f, core_server wg_pc_g, core_server wg_pc_h, core_server wg_pc_i, core_server wg_pc_j, core_server wg_pc_k, core_server wg_pc_l, core_server VLAN2 VLAN13 wg_ro_a e0/2e0 wg_ro_l e0e0/2

42 © 2004, Cisco Systems, Inc. All rights reserved. Visual Objective core_ server wg_sw_a wg_sw_l e0/1 fa0/26 (port A) e0/1 fa0/26 (port A) fa0/1 fa0/12 fa0/24 core_sw_a core_sw_b fa0/12 fa0/1 fa0/13 fa0/27 (port B) fa0/27 (port B) wg_pc_a wg_pc_l ISL 10.x.x.1 VLAN2 VLAN13 SUBNETVLANPOD wg_ro_x, wg_sw_x, core_sw_a, core_sw_b wg_pc_a, core_server wg_pc_b, core_server wg_pc_c, core_server wg_pc_d, core_server wg_pc_e, core_server wg_pc_f, core_server wg_pc_g, core_server wg_pc_h, core_server wg_pc_i, core_server wg_pc_j, core_server wg_pc_k, core_server wg_pc_l, core_server fa0/14...

43 © 2004, Cisco Systems, Inc. All rights reserved. Private network

44 © 2004, Cisco Systems, Inc. All rights reserved. Hybrid network

45 © 2004, Cisco Systems, Inc. All rights reserved. Virtual private networks

46 © 2004, Cisco Systems, Inc. All rights reserved. VPN techniques

47 © 2004, Cisco Systems, Inc. All rights reserved. Authentication

48 © 2004, Cisco Systems, Inc. All rights reserved. Encryption

49 © 2004, Cisco Systems, Inc. All rights reserved. Tunneling

50 © 2004, Cisco Systems, Inc. All rights reserved. Addressing in VPN

51 © 2004, Cisco Systems, Inc. All rights reserved. Summary After completing this chapter, you should be able to perform the following tasks: Configuring VLAN Configuring VTP Configuring a trunk Verifing Spanning Tree Operations

52 © 2004, Cisco Systems, Inc. All rights reserved. Review Questions 1. What are the three VTP modes? 2. Over what type of port can VTP advertisements be sent? 3. VLAN ID is carried in the ________ header. 4. How do we assign a VLAN to a port?